import { Callout } from "zudoku/ui/Callout";

# SEPA payment import: who may see the recipients

Two permission sets in 365 business Banking separate who only approves and executes a payroll file from who may see each recipient line.

A payroll file names every person and their salary. Users who approve or carry out the payment usually do not need this information. For this reason, [SEPA payment import](../sepa-payment-import.mdx) has two permission sets that differ in one point only: whether the lines are readable.

## Two permission sets

| Permission set | Sees | May |
|---|---|---|
| **Banking SEPA Import (no recipient details)** | the header: file, status, **Number of Payment Instructions**, **Total Amount**, bank account, approval status, **Carried Out At**, **Carried Out By** | import, **Parse**, **Validate**, request approval, **Reopen**, **Carry Out Payment**, **Print Payment Proof**, delete |
| **Banking SEPA Import (with recipient details)** | in addition every line with name, IBAN, amount and message, and the **Line Errors** FactBox | the same, plus **Verification of Payee (VoP)**, **Update Execution Dates** and **Make Collective Payment** |

The **Banking (Base)** set does not include SEPA payment import. Anyone who works with payment imports needs one of the two sets in addition. All permission sets of 365 business Banking are listed in [Permissions and licenses](../setup/permissions-and-licenses.mdx).

## What is hidden

With **Banking SEPA Import (no recipient details)**, the **SEPA Payment Import** card does not show the following elements:

- the **Lines** part and with it the line actions **Update Execution Dates** and **Make Collective Payment**,
- the **Line Errors** FactBox, because its messages name the line and thus the recipient,
- the **Verification of Payee (VoP)** action, because its result is written to the lines.

<Callout type="info" title="Permission, not just hiding">
The set grants permission for the lines only indirectly. Business Central reads the lines to parse, validate and pay. However, the person cannot read them on a page, through **Edit in Excel** or through the API. The **SEPA Payment Proof** reads only amount and currency from the lines, to total them per currency. It only shows the count and the total.
</Callout>

Without the lines, this person also cannot see which line has an error. If an import has the status *Error*, a user with the full set must check the lines.

## Recommendation

- Approvers and the accounting staff who trigger the payment get **Banking SEPA Import (no recipient details)**. For approval, the total amount and the count are relevant, and both are visible to these users.
- Only assign **Banking SEPA Import (with recipient details)** to users who must check the file's content (typically payroll) or who must resolve errors in the lines and have the recipients verified.
- Assign the sets like any other permission set. See [Assign permissions](https://learn.microsoft.com/en-us/dynamics365/business-central/ui-define-granular-permissions) on Microsoft Learn.

## See also

- [SEPA payment import](../sepa-payment-import.mdx)
- [Approval and verification of payee](approval-and-vop.mdx)
- [Payment proof and retention](payment-proof.mdx)
- [Permissions and licenses](../setup/permissions-and-licenses.mdx)
